From 3f8db3fdbc2235dee30f5c1ea206584ecabbe484 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 4 Feb 2024 07:16:20 +0000 Subject: [ GLSA 202402-07 ] Xen: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/754105 Bug: https://bugs.gentoo.org/757126 Bug: https://bugs.gentoo.org/826998 Bug: https://bugs.gentoo.org/837575 Bug: https://bugs.gentoo.org/858122 Bug: https://bugs.gentoo.org/876790 Bug: https://bugs.gentoo.org/879031 Bug: https://bugs.gentoo.org/903624 Bug: https://bugs.gentoo.org/905389 Bug: https://bugs.gentoo.org/915970 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202402-07.xml | 112 +++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 112 insertions(+) create mode 100644 glsa-202402-07.xml diff --git a/glsa-202402-07.xml b/glsa-202402-07.xml new file mode 100644 index 00000000..95702046 --- /dev/null +++ b/glsa-202402-07.xml @@ -0,0 +1,112 @@ + + + + Xen: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Xen, the worst of which can lead to arbitrary code execution. + xen + 2024-02-04 + 2024-02-04 + 754105 + 757126 + 826998 + 837575 + 858122 + 876790 + 879031 + 903624 + 905389 + 915970 + remote + + + 4.16.6_pre1 + 4.16.6_pre1 + + + +

Xen is a bare-metal hypervisor.

+
+ +

Multiple vulnerabilities have been discovered in Xen. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Xen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-emulation/xen-4.16.6_pre1" + +
+ + CVE-2021-28703 + CVE-2021-28704 + CVE-2021-28705 + CVE-2021-28706 + CVE-2021-28707 + CVE-2021-28708 + CVE-2021-28709 + CVE-2022-23816 + CVE-2022-23824 + CVE-2022-23825 + CVE-2022-26356 + CVE-2022-26357 + CVE-2022-26358 + CVE-2022-26359 + CVE-2022-26360 + CVE-2022-26361 + CVE-2022-27672 + CVE-2022-29900 + CVE-2022-29901 + CVE-2022-33746 + CVE-2022-33747 + CVE-2022-33748 + CVE-2022-33749 + CVE-2022-42309 + CVE-2022-42310 + CVE-2022-42319 + CVE-2022-42320 + CVE-2022-42321 + CVE-2022-42322 + CVE-2022-42323 + CVE-2022-42324 + CVE-2022-42325 + CVE-2022-42326 + CVE-2022-42327 + CVE-2022-42330 + CVE-2022-42331 + CVE-2022-42332 + CVE-2022-42333 + CVE-2022-42334 + CVE-2022-42335 + XSA-351 + XSA-355 + XSA-385 + XSA-387 + XSA-388 + XSA-389 + XSA-397 + XSA-399 + XSA-400 + XSA-407 + XSA-412 + XSA-414 + XSA-415 + XSA-416 + XSA-417 + XSA-418 + XSA-419 + XSA-420 + XSA-421 + XSA-422 + XSA-425 + XSA-430 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad